A critical Windows Netlogon remote code execution flaw, tracked as CVE-2026-41089, is being actively exploited against corporate networks, with attacks targeting Windows Server domain controllers. The vulnerability can be triggered through specially crafted Netlogon requests without authentication or user interaction, potentially allowing attackers to run arbitrary code with SYSTEM-level privileges and escalate to full domain compromise.
Microsoft patched the issue in its May 2026 Patch Tuesday release, which addressed 118 vulnerabilities, including 16 critical flaws, and the Centre for Cybersecurity Belgium flagged the Netlogon bug as a priority because of confirmed in-the-wild exploitation. Organizations are being urged to immediately patch supported Windows Server versions from 2012 onward, restrict domain controllers from untrusted network exposure, and increase monitoring for suspicious Netlogon and authentication activity while reinforcing segmentation and access controls around domain controllers.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
The Centre for Cybersecurity Belgium identified CVE-2026-41089 as a priority issue and confirmed that the Windows Netlogon flaw is being actively exploited in the wild. The vulnerability affects Windows Server domain controllers and can enable unauthenticated remote code execution with SYSTEM-level privileges.
Microsoft disclosed and patched the critical Windows Netlogon remote code execution vulnerability CVE-2026-41089 in its May 2026 Patch Tuesday release. The release reportedly addressed 118 vulnerabilities, including 16 critical issues.
Acros Security released micropatches for legacy Windows Server 2008 R2, 2012, and 2012 R2 systems to address CVE-2026-41089. The micropatches were presented as an option for older server versions alongside Microsoft's Patch Tuesday fixes for supported systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
secpod.com
Open sourcesecpod.com
Open sourcecert.europa.eu
Open sourcexakep.ru
Open sourcehelpnetsecurity.com
Open sourcesentinelone.com
Open sourcearetiq.ai
Open sourcesecpod.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.